6.5

CVE-2023-4580

Push notifications saved to disk unencrypted

Push notifications stored on disk in private browsing mode were not being encrypted potentially allowing the leak of sensitive information. This vulnerability affects Firefox < 117, Firefox ESR < 115.2, and Thunderbird < 115.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mozilla ≫ Firefox Version < 117.0
Mozilla ≫ Firefox ESR Version < 115.2
Mozilla ≫ Thunderbird Version < 115.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.42% 0.34
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CWE-311 Missing Encryption of Sensitive Data

The product does not encrypt sensitive or critical information before storage or transmission.

https://www.mozilla.org/security/advisories/mfsa2023-36/
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2023-38/
Vendor Advisory
https://www.mozilla.org/security/advisories/mfsa2023-34/
Vendor Advisory
https://bugzilla.mozilla.org/show_bug.cgi?id=1843046
Issue Tracking
Permissions Required